Privacy Policy

This Privacy Policy ("Policy") describes how Bhala AI ("Bhala," "we," "us," or "our") collects, uses, stores, and protects information when you use our website, APIs, developer console, mobile applications (including the Bhala Keyboard), and related services (collectively, the "Services"). By accessing or using our Services, you agree to the practices described in this Policy.

1. Information We Collect

1.1 Account Information

When you create a Bhala AI account or developer console account, we collect your name, email address, and password. This information is necessary to authenticate you, manage your account, and communicate with you about the Services.

1.2 Payment Information

When you purchase credits or subscribe to a paid plan, payment processing is handled by our third-party payment processor, Stripe. We do not directly store your full credit card number or bank account details. Stripe's collection and use of your information is governed by Stripe's Privacy Policy. We receive limited transaction information (such as the last four digits of your card, billing address, and transaction amount) for record-keeping and support purposes.

1.3 API Usage Data

When you use Bhala APIs (Embeddings, Translation, Reranker, and others), we collect metadata about your requests, including request timestamps, token counts, endpoint accessed, and response status codes. This data is used for billing, rate-limit enforcement, service monitoring, and to improve the quality and performance of our models and Services.

We do not store or retain the text content you submit through our APIs beyond what is necessary to process your request. Once a response is returned, the submitted text is discarded and is not used for model training unless you have explicitly opted in.

1.4 Bhala Keyboard Data

The Bhala Keyboard is designed to work offline. It does not transmit the content of what you type to our servers in real time. The keyboard may collect anonymized, aggregated typing pattern data (such as word frequency statistics and autocorrect interaction data) to improve language models, autocomplete accuracy, and spell-correction quality for supported African languages. This data is:

  • Anonymized — it is stripped of personally identifiable information before transmission.
  • Aggregated — individual keystrokes, passwords, credit card numbers, and other sensitive fields are never collected or transmitted.
  • Optional — you may disable analytics data sharing in the keyboard's settings at any time without affecting core functionality.

The Bhala Keyboard does not collect, store, or transmit passwords, financial information, health data, or any content from encrypted or private message fields.

1.5 Contact and Communication Data

When you contact us through our website contact form, email, or other channels, we collect your name, email address, and the content of your message. We use this information to respond to your inquiry and may retain it for quality assurance and support purposes.

1.6 Automatically Collected Information

When you visit our website or use the developer console, we may automatically collect certain technical information, including your IP address, browser type and version, operating system, referring URL, pages visited, and the date and time of your visit. This information is collected through standard web server logs and may be used with cookies or similar technologies to maintain session state and improve the user experience.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Services;
  • Process transactions and manage billing;
  • Authenticate users and secure accounts;
  • Monitor and enforce API usage limits and terms of service compliance;
  • Improve, personalize, and develop new features for our language models, APIs, and applications;
  • Respond to customer support requests and communicate with you about the Services;
  • Send transactional emails (e.g., account verification, billing receipts, usage alerts);
  • Detect, prevent, and address fraud, abuse, security incidents, and technical issues;
  • Comply with legal obligations and enforce our agreements.

3. Anonymization

Where we use data to improve our Services (such as aggregated API usage statistics or Bhala Keyboard typing patterns), that data is anonymized and stripped of all personally identifiable information before processing. Anonymized data cannot be traced back to any individual user. Once data has been anonymized, it is no longer considered personal information under this Policy.

4. Data Sharing and Disclosure

We do not sell, rent, trade, or otherwise share your personal information with third parties for their own commercial or marketing purposes — under any circumstances. Your data is yours. We will never monetize it by selling or providing it to advertisers, data brokers, or any other external company.

We may share limited information with third parties only in the following narrowly defined circumstances:

  • Essential service providers: We use a small number of third-party service providers strictly necessary to operate our Services: Stripe (payment processing) and Supabase (authentication and database hosting). These providers receive only the minimum information needed to perform their functions and are contractually prohibited from using your data for any other purpose.
  • Legal requirements: We may disclose information if compelled by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and ensure the acquiring entity is bound by the same data protection commitments in this Policy.

We do not share data with advertising networks, analytics companies, or any third party beyond what is listed above.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Services. API usage metadata is retained for billing, compliance, and service improvement purposes. If you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements, or complying with legal obligations).

6. Data Security

We implement industry-standard technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS/SSL), secure password hashing, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to maintain your session state, remember your preferences, and secure the developer console. These are essential cookies necessary for the functioning of the Services. We do not use third-party advertising or tracking cookies. You can configure your browser to refuse cookies, but this may affect your ability to use certain features of the Services.

8. Your Rights and Choices

Depending on your location, you may have the right to:

  • Access the personal information we hold about you;
  • Correct inaccurate or incomplete personal information;
  • Delete your personal information, subject to certain exceptions;
  • Export your data in a portable format;
  • Withdraw consent where processing is based on consent;
  • Object to or restrict certain types of processing.

To exercise any of these rights, please contact us at legal@bhala.ai. We will respond to your request within 30 days.

9. Children's Privacy

Our Services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at legal@bhala.ai.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including countries that may not have the same data protection laws. By using the Services, you consent to the transfer of your information to these countries. We take appropriate safeguards to ensure your information remains protected in accordance with this Policy.

11. Third-Party Links

Our Services may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated Policy on our website and updating the "Last updated" date below. Your continued use of the Services after such changes constitutes your acceptance of the revised Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Last updated: February 2026